Not Safe for Work: Tracking and Investigating Stealerium and Phantom Infostealers

Sept. 4, 2025, 8:16 a.m.

Description

Proofpoint researchers have observed an increase in cybercriminals using Stealerium-based malware, an open-source infostealer available on GitHub. Multiple stealers share code with Stealerium, including Phantom Stealer. Campaigns delivering Stealerium have used various lures and file types, targeting industries like hospitality, education, and finance. The malware can exfiltrate a wide range of data, including browser credentials, credit card info, and crypto wallet data. It uses anti-analysis techniques and can exfiltrate data through multiple channels like SMTP, Discord, and Telegram. The rise in Stealerium usage reflects the growing trend of threat actors pivoting to information stealers as identity theft becomes a priority.

Date

  • Created: Sept. 4, 2025, 12:59 a.m.
  • Published: Sept. 4, 2025, 12:59 a.m.
  • Modified: Sept. 4, 2025, 8:16 a.m.

Indicators

  • e590552eea3ad225cfb6a33fd9a71f12f1861c8332a6f3a8e2050fffce93f45e
  • d4a33be36cd0905651ce69586542ae9bb5763feddc9d1af98e90ff86a6914c0e
  • b640251f82684d3b454a29e962c0762a38d8ac91574ae4866fe2736f9ddd676e
  • a00fda931ab1a591a73d1a24c1b270aee0f31d6e415dfa9ae2d0f126326df4bb
  • 41700c8fe273e088932cc57d15ee86c281fd8d2e771f4e4bf77b0e2c387b8b23
  • 50927b350c108e730dc4098bbda4d9d8e7c7833f43ab9704f819e631b1d981e3
  • https://phantomsoftwares.site/home/.
  • phantomsoftwares.site

Attack Patterns

  • Warp Stealer
  • Phantom Stealer
  • Snake Keylogger
  • Stealerium
  • TA2715

Additional Informations

  • Hospitality
  • Education
  • Finance
  • Canada